IP Library Granted Patent US 11,128,652
Granted Patent B1
US 11,128,652 · App. 16/170,962 · Granted Sep 21, 2021

Dynamic vulnerability correlation

Inventors: Tyler Reguly (Toronto, CA); Chris Pawlukowsky (Alpharetta, GA); Matthew Jonathan Condren (Cumming, GA)
Assignee: Tripwire, Inc.
H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,128,652
App. No.
16/170,962
Granted
Sep 21, 2021
Kind
B1
Abstract

Apparatus and methods are disclosed for performing dynamic vulnerability correlation suitable for use in enterprise information technology (IT) environments, including vulnerability filtering, patch correlation, and vulnerability paring. According to one disclosed embodiment, a method of vulnerability filtering includes attempting to execute vulnerability scanning rules according to a specified order in a rule hierarchy, and depending on the type of the rule hierarchy and on whether the attempt was successful, not executing additional rules in the rule hierarchy. In another disclosed embodiment, a method of patch correlation includes executing vulnerability scanning rules based on a correlation associations including, if a particular vulnerability is detected, then not executing other correlated scanning rules for a particular software patch. In another disclosed embodiment, a method of vulnerability paring includes defining a plurality of patch milestones for a software product and scanning a target computer for vulnerabilities associated with a current installed patch.

Claims (30)

1. A method of patch correlation for a set of scanning rules, the method comprising:

identifying a platform associated with a target computer;

producing a database including one or more correlation associations between a set of two or more vulnerabilities referenced in a software bulletin, each vulnerability having a corresponding separate scanning rule that, when executed, scans the target computer for the vulnerability;

executing a first scanning rule to determine the existence in the target computer of a corresponding first one of the vulnerabilities in the set of vulnerabilities, the executing comprising only executing scanning rules that are relevant to the identified target computer platform; and

based on the determined existence of the first vulnerability and at least one of the correlation associations, designating the other vulnerabilities in the set of vulnerabilities as existing in the target computer without executing remaining ones of the scanning rules corresponding to the other vulnerabilities.

2. The method of claim 1 , further comprising generating rule groups for additional software bulletins on a per-bulletin basis, the rule groups being used to generate additional correlation associations between vulnerabilities referenced in the additional software bulletins.

3. The method of claim 1 , further comprising:

caching scanning rules associated with a set of software patches corresponding to the software bulletin,

wherein additional scanning rule executions or cache hits are removed or ignored based on the determined existence of the first vulnerability and the at least one of the correlation associations.

4. The method of claim 1 , further comprising analyzing additional software bulletins and reporting software patches determined to be missing from the target computer by the executed first scanning rule.

5. The method of claim 1 , wherein the scanning rules to be executed are determined at least in part using a vulnerability filtering technique.

6. The method of claim 1 , wherein the scanning rules to be executed are determined at least in part using a vulnerability paring technique.

7. The method of claim 1 , further comprising reporting the existence of vulnerabilities determined using the scanning rules grouped at least in part on a per-bulletin basis.

8. The method of claim 1 , further comprising:

based on the vulnerabilities determined or designated as existing, identifying a set of one or more software patches associated with the software bulletin that, when installed in the target computer, resolve the set of two or more vulnerabilities referenced in the software bulletin.

9. One or more non-transitory computer-readable storage media storing computer-readable instructions that when executed by a computer, cause the computer to perform operations, the operations comprising:

identifying a platform associated with a target computer;

producing a database including one or more correlation associations between a set of two or more vulnerabilities referenced in a software bulletin, each vulnerability having a corresponding separate scanning rule that, when executed, scans the target computer for the vulnerability;

executing a first scanning rule to determine the existence in the target computer of a corresponding first one of the vulnerabilities in the set of vulnerabilities, the executing comprising only executing scanning rules that are relevant to the identified target computer platform; and

based on the determined existence of the first vulnerability and at least one of the correlation associations, designating the other vulnerabilities in the set of vulnerabilities as existing in the target computer without executing remaining ones of the scanning rules corresponding to the other vulnerabilities.

10. The one or more non-transitory computer-readable storage media of claim 9 , wherein the operations further comprise generating rule groups for additional software bulletins on a per-bulletin basis, the rule groups being used to generate additional correlation associations between vulnerabilities referenced in the additional software bulletins.

11. The one or more non-transitory computer-readable storage media of claim 9 , wherein the operations further comprise:

caching scanning rules associated with a set of software patches corresponding to the software bulletin,

wherein additional scanning rule executions or cache hits are removed or ignored based on the determined existence of the first vulnerability and the at least one of the correlation associations.

12. The one or more non-transitory computer-readable storage media of claim 9 , wherein the operations further comprise analyzing additional software bulletins and reporting software patches determined to be missing from the target computer by the executed first scanning rule.

13. The one or more non-transitory computer-readable storage media of claim 9 , wherein the scanning rules to be executed are determined at least in part using a vulnerability filtering technique.

14. The one or more non-transitory computer-readable storage media of claim 9 , wherein the scanning rules to be executed are determined at least in part using a vulnerability paring technique.

15. The one or more non-transitory computer-readable storage media of claim 9 , wherein the operations further comprise reporting the existence of vulnerabilities determined using the scanning rules grouped at least in part on a per-bulletin basis.

16. The one or more non-transitory computer-readable storage media of claim 9 , wherein the operations further comprise:

based on the vulnerabilities determined or designated as existing, identifying a set of one or more software patches associated with the software bulletin that, when installed in the target computer, resolve the set of vulnerabilities referenced in the software bulletin.

Assignments (11)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0365 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0235 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0555 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: TRIPWIRE, INC.
Reel/Frame 074023/0320 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0639 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 60306/0649 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: TRIPWIRE, INC.
Reel/Frame 073663/0698 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073664/0124 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0365 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Jun 7, 2022
From: TRIPWIRE, INC.
To: GOLUB CAPITAL MARKETS LLC, AS COLLATERAL AGENT
Reel/Frame 060306/0649 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 12, 2019
From: REGULY, TYLER; PAWLUKOWSKY, CHRIS; CONDREN, MATTHEW JONATHAN
To: TRIPWIRE, INC.
Reel/Frame 048869/0717 →
Continuity (3)
Division 14165410 · Jan 27, 2014
Provisional Application 61892318 · Oct 17, 2013
Provisional Application 61922679 · Dec 31, 2013